HIPAA compliance for telehealth brands
A signed BAA is the contractual floor, not the achievement. What HIPAA actually requires of a direct-to-consumer telehealth operation, and where brands most often get it wrong.
Key takeaways
- A Business Associate Agreement is required with any vendor handling protected health information. Without one, disclosing PHI to them is itself a violation.
- A BAA is the contract layer. Encryption, access control and audit logging are what actually protect the data.
- PHI is broader than diagnoses: an email address becomes PHI once tied to care or payment for care.
- Marketing tooling is where most brands create exposure, by segmenting on treatment type inside general-purpose platforms.
- If your platform is breached, the notification obligation reaches your patients under your brand.
Who is the covered entity, and who is the business associate
In a standard MSO structure the professional entity providing clinical care is the covered entity. The software platform, and typically the management company, operate as business associates under executed agreements.
This matters because it determines who carries the notification obligation when something goes wrong, and who is directly liable to regulators. It is worth asking any infrastructure vendor to state plainly which role they occupy in their standard structure.
What actually counts as PHI
Protected health information is individually identifiable health information held or transmitted by a covered entity or business associate. The common misunderstanding is that it means diagnoses.
It does not. Names, addresses, dates, contact details and payment information all become PHI once associated with health status, care, or payment for care. In a telehealth operation that means intake responses, provider messages, prescription records, shipment addresses and much of the billing data are all in scope.
The safeguards behind the paperwork
HIPAA requires administrative, physical and technical safeguards. In practice, for a software-delivered telehealth operation, these are the ones to verify with any vendor.
- Encryption in transit and at rest for stored protected health information, including clinical records and message threads.
- Role-based access control on least privilege, so records are reachable by the people whose function requires them rather than everyone with a login.
- Audit logging on record access as well as clinical and billing events, queryable per patient.
- Breach notification procedures with defined timelines, so you learn fast enough for your own obligations to be met.
- Provider credential verification before any clinician touches a patient record.
Where brands most often go wrong
Very few HIPAA problems in direct-to-consumer telehealth originate in the clinical system. They originate in marketing.
Pushing a patient list into a general-purpose email platform and segmenting it by treatment type creates PHI inside a tool that almost certainly has no BAA in place. The same applies to analytics and advertising pixels that capture URL paths or event names describing a condition.
The fix is not complicated but it has to be deliberate: keep condition-level segmentation inside systems covered by a BAA, and be careful about what page paths and event names reveal.
What to ask a platform, specifically
Vague reassurance is common here, so ask for specifics and treat a non-specific answer as an answer.
- Do you sign a BAA as standard, on every tier, including the entry plan?
- Who is the covered entity in your standard structure?
- Is PHI encrypted at rest as well as in transit?
- Can I query an audit trail per patient, or only you?
- What is your breach notification timeline to me, in the agreement?
- Can I export all of my patient data, and how fast?
BAA as standard, and an export you never have to ask twice for
PharmaBro signs a Business Associate Agreement as standard on every tier, with encryption in transit and at rest, role-based access control and per-patient audit logging behind it.
The strongest protection is structural rather than contractual: because your brand owns the Stripe account and there is no contract term, your payment data sits outside our systems entirely, and a full export of records, order history and card tokens is available within 24 hours on any day you ask.
Conclusion
HIPAA compliance is not a badge. It is an executed agreement plus a set of controls plus operational discipline about where patient data is allowed to travel.
Get the BAA. Verify the controls behind it rather than accepting the contract as evidence of them. And audit your marketing stack, because that is where the exposure usually is.
Frequently asked questions
Is a signed BAA enough to be HIPAA compliant?
No. It is the contractual requirement, not the substance. Compliance also requires the administrative, physical and technical safeguards behind it. Ask a vendor to describe those specifically rather than treating the signed agreement as proof.
Is a patient's email address PHI?
Once associated with their care or payment for care, yes. This is why marketing tooling in telehealth needs the same care as clinical systems, and why segmenting a list by treatment type inside a general-purpose email platform is riskier than it appears.
What happens if my platform has a breach?
The notification obligation reaches your patients under your brand, on records you did not control. This is why the breach notification terms in a BAA matter more than operators usually assume: they determine how quickly you find out.
Priya RaghunathanHead of Compliance Operations
Handles LegitScript, HIPAA posture, MSO structuring and state coverage. Writes the parts of this blog that operators wish someone had told them before they signed.

